Re: RRSIGs in additional section

Tony Finch <[email protected]> Fri, 15 Nov 2013 14:06:05 +0000
Newsgroups gmane.ietf.dnsext
Message-ID <[email protected]>
Kumar Ashutosh <[email protected]> wrote:
>
> As per RFC 4035 section 3.1.1
>
> When placing a signed RRset in the Additional section, the name server
> MUST also place its RRSIG RRs in the Additional section. If space does
> not permit inclusion of both the RRset and its associated RRSIG RRs, the
> name server MAY retain the RRset while dropping the RRSIG RRs.  If this
> happens, the name server MUST NOT set the TC bit solely because these
> RRSIG RRs didn't fit.

This is sort-of consistent with RFC 2181 (depending on whether you view
the RRSIG as part of the RRset or not):

9. The TC (truncated) header bit

   The TC bit should be set in responses only when an RRSet is required
   as a part of the response, but could not be included in its entirety.
   The TC bit should not be set merely because some extra information
   could have been included, but there was insufficient room.  This
   includes the results of additional section processing.  In such cases
   the entire RRSet that will not fit in the response should be omitted,
   and the reply sent as is, with the TC bit clear.  If the recipient of
   the reply needs the omitted data, it can construct a query for that
   data and send that separately.

   Where TC is set, the partial RRSet that would not completely fit may
   be left in the response.  When a DNS client receives a reply with TC
   set, it should ignore that response, and query again, using a
   mechanism, such as a TCP connection, that will permit larger replies.

> If such a response is received by a caching resolver it may Cache the
> RRSet in additional section without their RRSIGs and subsequent queries
> from this resolver might be responded without RRSIGs.

No. See RFC 2181 section 5.4.1:

   Unauthenticated RRs received and cached from the least trustworthy of
   those groupings, that is data from the additional data section, and
   data from the authority section of a non-authoritative answer, should
   not be cached in such a way that they would ever be returned as
   answers to a received query.  They may be returned as additional
   information where appropriate.  Ignoring this would allow the
   trustworthiness of relatively untrustworthy data to be increased
   without cause or excuse.

Tony.
-- 
f.anthony.n.finch  <[email protected]>  http://dotat.at/
Forties, Cromarty: East, veering southeast, 4 or 5, occasionally 6 at first.
Rough, becoming slight or moderate. Showers, rain at first. Moderate or good,
occasionally poor at first.
_______________________________________________
dnsext mailing list
[email protected]
https://www.ietf.org/mailman/listinfo/dnsext